# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 70 → 74 (+4.4)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

## Lenses

- Code Health 81 → 81 (-0.5)
- Architecture 98 → 96 (-2.4)
- Maturity 75 → 75 (-0.3)
- Readiness 68 → 68 (+0.4)
- Security 62 → 74 (+12.4)
- Event Sourcing 100 → 100 (+0.0)
- Performance 100 (new)

## Resolved (44)

- BaseDocument::compute_child_layout_internal (cognitive 46) (packages/blitz-dom/src/layout/mod.rs)
- BaseDocument::compute_child_layout_internal (cyclomatic 30) (packages/blitz-dom/src/layout/mod.rs)
- BaseDocument::flush_styles_to_layout_impl (cognitive 29) (packages/blitz-dom/src/layout/damage.rs)
- BaseDocument::flush_styles_to_layout_impl (cyclomatic 16) (packages/blitz-dom/src/layout/damage.rs)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (11 lines × 2) (packages/blitz-dom/src/node/node.rs)
- Duplicated block (12 lines × 2) (packages/blitz-paint/src/render.rs)
- Duplicated block (5 lines × 3) (packages/blitz-dom/src/font_metrics.rs)
- Duplicated block (8 lines × 2) (packages/blitz-dom/src/font_metrics.rs)
- FunctionTooLong: blitz_dom::layout::inline::layout_abspos_child (packages/blitz-dom/src/layout/inline.rs)
- HackComment (packages/blitz-dom/src/layout/construct.rs)
- HackComment (packages/blitz-dom/src/layout/inline.rs)
- High: security finding (details withheld)
- Hotspot: apps/browser/src/toolbar.rs (apps/browser/src/toolbar.rs)
- Hotspot: packages/blitz-dom/src/accessibility.rs (packages/blitz-dom/src/accessibility.rs)
- Hotspot: packages/blitz-dom/src/cssom.rs (packages/blitz-dom/src/cssom.rs)
- Hotspot: packages/blitz-dom/src/events/mod.rs (packages/blitz-dom/src/events/mod.rs)
- Hotspot: packages/blitz-dom/src/layout/list.rs (packages/blitz-dom/src/layout/list.rs)
- Hotspot: packages/blitz-dom/src/node/text.rs (packages/blitz-dom/src/node/text.rs)
- …and 24 more

## New (43)

- Ambiguous return type for mutator methods. `get_node_mut` returns `Node` (likely a value or wrapper) rather than a mutable reference `&mut Node` or a guard type, making it unclear if the mutation is immediate or deferred. This contrasts with `Document.inner_mut()` which returns a `DocGuardMut`.
- BaseDocument::build_paint_tree_impl (cognitive 30) (packages/blitz-dom/src/layout/paint_tree.rs)
- BaseDocument::build_paint_tree_impl (cyclomatic 16) (packages/blitz-dom/src/layout/paint_tree.rs)
- BaseDocument::dispatch_child_layout (cognitive 53) (packages/blitz-dom/src/layout/mod.rs)
- BaseDocument::dispatch_child_layout (cyclomatic 32) (packages/blitz-dom/src/layout/mod.rs)
- BaseDocument::propagate_damage_flags (cyclomatic 16) (packages/blitz-dom/src/layout/damage.rs)
- BaseDocument::resolve_transforms (cognitive 20) (packages/blitz-dom/src/resolve.rs)
- Confusing naming and return types for root access. `root_node` and `root_element` likely refer to the same underlying node (the `<html>` or document root), but one is 'try' (implying it might fail) and the other doesn't. Furthermore, `root_node_mut` returns `Node` instead of a mutable guard/reference, inconsistent with the `inner_mut` pattern.
- Duplicate functionality across types. `BaseDocument` and `DocumentMutator` both expose `set_style_property` and `remove_style_property`. Since `DocumentMutator` is obtained via `BaseDocument.mutate()`, it is unclear if calling these on `BaseDocument` directly is valid or if it bypasses the mutation tracking system.
- Duplicated block (10–11 lines × 2) (packages/blitz-dom/src/node/element.rs)
- Duplicated block (12 lines × 2) (packages/blitz-dom/src/node/node.rs)
- Duplicated block (13 lines × 2) (packages/blitz-paint/src/render.rs)
- Duplicated block (14–15 lines × 2) (packages/blitz-dom/src/layout/construct.rs)
- Duplicated block (8 lines × 2) (packages/blitz-dom/src/font_metrics.rs)
- FunctionTooLong: blitz_paint::text::flush_line_decorations (packages/blitz-paint/src/text.rs)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Inconsistent scroll API design. `scroll_to` and `scroll_by` take a `NodeId` and `ScrollBehavior`, while `scroll_node_by` takes a callback `dispatch_event` and no behavior enum. `scroll_viewport_by` lacks behavior. The presence of `_has_changed` variants suggests a need for atomic check-and-set operations that are not consistently applied to all scroll methods.
- Inverted test pyramid
- Low cohesion: BlitzShellProvider (LCOM4 4) (packages/blitz-shell/src/lib.rs)
- …and 23 more

## Changes since last survey

- 55 commits — 52 feature/other, 3 fixes

## By area

- packages/blitz-dom — 37 commits
- (root) — 8 commits
- .github/workflows — 5 commits
- packages/stylo_taffy — 3 commits
- apps/readme — 1 commit
- wpt/runner — 1 commit

## Notable commits

- fix: Fix hit-testing of hoisted children under a scrolled stacking-context root; move viewport_scroll into NodeTree (#944)
- fix: Fix unused NodeFlags import warning in release builds
- fix: Implement out-of-flow hoisting (`position:absolute` and `position:fixed`)  (#922)
- change: Add UA rule mapping td/th nowrap attribute to white-space: nowrap (#931)
- change: Apply translate/rotate/scale in the correct order (T·R·S) (#934)
- change: Build the paint tree in a single damage-gated post-layout pass (#921)
- change: Bump Taffy: don't stretch absolutely positioned replaced elements between insets (#972)
- change: Bump Taffy: only resolve abspos auto margins when both insets are set (#971)
- change: Bump Taffy: respect the root element's position and insets (#976)
- change: Bump Taffy: viewport-sized initial containing block (#973)
- change: Bump pinned WPT revision to 375cf2548 (2026-09-28) (#970)
- change: Bump pinned WPT revision to `d552535bc` (2026-09-17) (#907)
- change: Bump taffy to main (out-of-flow refactor) (#912)
- change: CI: Add weekly job that bumps the pinned WPT revision (#908)
- change: Clamp an inline box's height to a finite value (#941)
- change: Clear stale stacking_context when a node stops being a stacking context root (#913)
- change: Compute ch/ic advances with the same scaling as Parley's glyph advances (#927)
- change: Don't clamp replaced elements' max size to the available space (#937)
- change: Don't count the empty line Parley adds after a final forced line break in inline height (#939)
- change: Don't drop whitespace-only text nodes whose whitespace is preserved (#930)
- …and 35 more
